Trust Center

Security & compliance at DeviceCloud

Moropo Limited (trading as DeviceCloud) is committed to protecting customer data. This page explains the controls, policies, and practices behind our platform.

View documents →

Policies available to customers and prospects under NDA.

How we protect your data

Security is built into how we operate. Our programme is underpinned by a set of written policies that are reviewed regularly and apply to everyone at the company.

Encryption

Customer data is encrypted in transit and at rest using industry-standard algorithms, governed by our Encryption Policy.

Access Control

Least-privilege access, enforced authentication, and regular access reviews protect every system we operate.

Backups & Recovery

Critical data is backed up and tested so we can recover quickly from corruption, deletion, or failure.

Change Management

Changes to production systems follow a reviewed, auditable process to keep our platform stable and secure.

Incident Response

Documented playbooks let us detect, contain, and communicate security incidents promptly and transparently.

Vendor Management

Third-party vendors are assessed and monitored for security before and throughout our use of their services.

Reports & certifications

Our audit and assurance documents. Some are available to everyone; others require you to accept a short non-disclosure agreement, after which we email you a secure, time-limited link.

Security Overview

Public

A one-page summary of our security programme. No NDA required.

Download →

SOC 2 Type II Report

NDA

Our latest SOC 2 Type II report. Available to reviewers under NDA.

Request access →

Penetration Test Report

NDA

Full third-party penetration test report. Available to reviewers under NDA.

Request access →

Policies & documents

The policies that govern our security programme are available to customers and prospects under NDA. Request access and our team will share the latest signed copies.

Acceptable Use Policy

Defines the acceptable use of company computer equipment and systems to safeguard sensitive customer data.

Request →

Access Control Policy

Establishes the principles and guidelines for controlling access to systems owned by DeviceCloud.

Request →

Authentication and Password Policy

Sets requirements for account authentication, including how passwords are generated, used, and protected.

Request →

Backup Policy

Institutes controls to mitigate accidental loss, corruption, or deletion of company and customer data.

Request →

Change Management Policy

Guides the process of safely managing change across critical systems and products.

Request →

Data Classification Policy

Defines a framework for determining the sensitivity of company data and systems and how to handle it.

Request →

Data Retention and Disposal Policy

Establishes how long data is retained and how it is securely disposed of to protect confidentiality.

Request →

Encryption Policy

Establishes practices for protecting data through encryption, both in transit and at rest.

Request →

Human Resources Policy

Sets requirements for attracting, developing, and retaining competent, security-conscious personnel.

Request →

Security Incident Management Policy

Establishes plans for reporting and responding to security incidents affecting corporate or customer systems.

Request →

Vendor Management Policy

Governs the selection, acquisition, and ongoing management of third-party vendors and their security.

Request →

Subprocessors

We use a small number of trusted third-party providers to deliver our service. Each is assessed under our Vendor Management Policy. The devices that run your apps are hosted on our own on-premises hardware, not a third-party cloud.

Provider Purpose Data processed Region
Supabase Primary database, authentication, and file storage Account data, user credentials, uploaded files
Backblaze B2 Object storage for test artifacts Screenshots, recordings, app binaries
Paddle Payments and subscription billing (Merchant of Record) Billing and contact details
Resend Transactional email delivery Email addresses, message content
Twilio SMS and phone messaging Phone numbers, message content
Google Workspace Identity provider (SSO) and business email Authentication data, correspondence
Anthropic AI-powered customer support assistant Support conversation content
Axiom Application logging and observability Application and access logs
BetterStack Uptime monitoring and log management Operational logs, uptime data

Questions about our subprocessors? Email security@devicecloud.dev.

Have a security question?

Our team is happy to help with security reviews, due-diligence questionnaires, and document requests.